CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 1 of 85
- CVE-1999-0039HIGHCVSS 7.3EG 7.31997-05-06
webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.
- CVE-2005-2773CRITICALCVSS 9.8EG 9.8⚠ KEV2005-09-02
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
- CVE-2005-2793HIGHCVSS v2 7.5EG 7.52005-09-02
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.
- CVE-2007-3010CRITICALCVSS 9.8EG 9.8⚠ KEV2007-09-18
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
- CVE-2008-7313CRITICALCVSS 9.8EG 9.82017-03-31
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
- CVE-2008-7315CRITICALCVSS 9.8EG 9.82017-10-10
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
- CVE-2008-7319CRITICALCVSS 9.8EG 9.82017-11-07
The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitra…
- CVE-2009-5156CRITICALCVSS 9.8EG 9.82019-06-11
An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query string.
- CVE-2009-5157HIGHCVSS 8.8EG 8.82019-06-11
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.
- CVE-2010-0136HIGHCVSS v2 9.3EG 9.32010-02-16
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
- CVE-2010-2008LOWCVSS v2 3.5EG 3.52010-07-13
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), .…
- CVE-2010-4345CRITICALCVSS 7.8EG 9.0⚠ KEV2010-12-14
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_direc…
- CVE-2010-5330CRITICALCVSS 9.8EG 9.8⚠ KEV2019-06-11
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP pro…
- CVE-2011-4182HIGHCVSS 7.3EG 8.12018-06-12
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
- CVE-2012-1823CRITICALCVSS 9.8EG 9.8⚠ KEV2012-05-11
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitra…
- CVE-2012-4086MEDIUMCVSS v2 5.1EG 5.12013-09-25
A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790.
- CVE-2013-2513CRITICALCVSS 9.8EG 9.82023-12-12
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
- CVE-2013-2516HIGHCVSS 8.8EG 8.82019-02-15
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.
- CVE-2013-2810HIGHCVSS v2 10.0EG 10.02014-12-08
Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack.
- CVE-2013-4663HIGHCVSS v2 7.5EG 7.52014-12-28
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the…
- CVE-2013-6924CRITICALCVSS 9.8EG 9.82017-10-11
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
- CVE-2013-7377HIGHCVSS 8.1EG 8.12017-10-23
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
- CVE-2013-7416HIGHCVSS v2 7.5EG 7.52014-12-03
canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.
- CVE-2013-7418MEDIUMCVSS v2 6.5EG 6.52015-01-02
cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacters in the TABLE parameter. NOTE: this can be exploited remotely by leveraging a separate …
- CVE-2013-7471CRITICALCVSS 9.8EG 9.82019-06-11
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the New…
- CVE-2014-0773HIGHCVSS v2 7.5EG 7.52014-04-12
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbitrary command lines. After validation, the values supplied in the HTML are passed to t…
- CVE-2014-10075CRITICALCVSS 9.8EG 9.82018-10-05
The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
- CVE-2014-1203CRITICALCVSS 9.8EG 9.82017-10-24
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.
- CVE-2014-1834HIGHCVSS 7.8EG 7.82018-02-02
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
- CVE-2014-1905HIGHCVSS v2 10.0EG 10.02014-12-29
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extensi…
- CVE-2014-3114CRITICALCVSS 9.8EG 9.82018-04-10
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php.
- CVE-2014-3524HIGHCVSS v2 9.3EG 9.32014-08-26
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
- CVE-2014-3556MEDIUMCVSS v2 6.8EG 6.82014-12-29
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert command…
- CVE-2014-3741CRITICALCVSS 9.8EG 9.82017-10-23
The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.
- CVE-2014-4336MEDIUMCVSS v2 5.8EG 5.82014-06-22
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists be…
- CVE-2014-4677HIGHCVSS 7.8EG 7.82017-02-22
The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument.
- CVE-2014-4982CRITICALCVSS 9.8EG 9.82020-01-10
LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.
- CVE-2014-5008CRITICALCVSS 9.8EG 9.82017-03-31
Snoopy allows remote attackers to execute arbitrary commands.
- CVE-2014-5009CRITICALCVSS 9.8EG 9.82017-03-31
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
- CVE-2014-5014CRITICALCVSS 9.8EG 9.82018-04-25
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
- CVE-2014-5220HIGHCVSS 7.8EG 7.82018-06-08
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
- CVE-2014-5470CRITICALCVSS 9.8EG 9.82024-06-21
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.
- CVE-2014-6120CRITICALCVSS 9.8EG 9.82018-04-12
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the i…
- CVE-2014-6260MEDIUMCVSS v2 6.8EG 6.82014-12-15
Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of service (paging outage) by leveraging an unattended workstati…
- CVE-2014-6633HIGHCVSS 8.8EG 8.82018-04-12
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to execute arbitrary commands via shell metacharacters in (1)…
- CVE-2014-7208HIGHCVSS v2 7.2EG 7.22014-12-19
GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.
- CVE-2014-7209HIGHCVSS v2 7.5EG 7.52015-01-06
run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
- CVE-2014-7285MEDIUMCVSS v2 6.5EG 6.52014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.
- CVE-2014-8515MEDIUMCVSS v2 6.8EG 6.82014-12-12
The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.
- CVE-2014-8517HIGHCVSS v2 7.5EG 7.52014-11-17
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the …
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →